56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.855 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-31968 | HIGH 7.5 | microsoft windows_10 Windows Remote Desktop Services Denial of Service Vulnerability | 3.2% | — |
| CVE-2010-4686 | HIGH 7.8 | cisco ios CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" request size, which allows remote attackers to cause a denial of service (memory consumption) by sending this traffic | 3.2% | — |
| CVE-2010-4683 | HIGH 7.8 | cisco ios Memory leak in Cisco IOS before 15.0(1)XA5 might allow remote attackers to cause a denial of service (memory consumption) by sending a crafted SIP REGISTER message over UDP, aka Bug ID CSCtg41733. | 3.2% | — |
| CVE-2009-5038 | HIGH 7.8 | cisco ios Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a certain IRC server, related to a | 3.2% | — |
| CVE-2026-25187 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2021-28586 | HIGH 7.8 | adobe after_effects After Effects version 18.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a ma | 3.2% | — |
| CVE-2020-1241 | HIGH 7.8 | microsoft windows_10 A security feature bypass vulnerability exists when Windows Kernel fails to properly sanitize certain parameters.To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system.The update | 3.2% | — |
| CVE-2023-29303 | MED 5.5 | adobe acrobat Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such a | 3.2% | — |
| CVE-2018-19706 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out | 3.2% | — |
| CVE-2018-16031 | HIGH 7.5 | adobe acrobat_dc Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out | 3.2% | — |
| CVE-2018-0456 | HIGH 7.7 | cisco nx-os A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application of an affected device to restart unexpectedly. The vulnerability is due | 3.2% | — |
| CVE-2017-12230 | HIGH 8.8 | cisco ios_xe A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who a | 3.2% | — |
| CVE-2007-3384 | MED 4.3 | apache tomcat Multiple cross-site scripting (XSS) vulnerabilities in examples/servlet/CookieExample in Apache Tomcat 3.3 through 3.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Value field, related to error messages. | 3.2% | — |
| CVE-2022-22971 | MED 6.5 | netapp cloud_secure_agent In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | 3.2% | — |
| CVE-2009-1265 | MED 5.0 | linux linux_kernel Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent. | 3.2% | — |
| CVE-2006-4650 | LOW 2.6 | cisco ios Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory loc | 3.2% | — |
| CVE-2025-14766 | HIGH 8.8 | google chrome Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 3.2% | — |
| CVE-2013-3468 | HIGH 7.8 | cisco unified_ip_phone_8945 The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka Bug ID CSCud04270. | 3.2% | — |
| CVE-2020-17053 | HIGH 7.5 | microsoft internet_explorer Internet Explorer Memory Corruption Vulnerability | 3.2% | — |
| CVE-2019-19076 | MED 5.9 | canonical ubuntu_linux A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. NOTE: This has been argued as n | 3.2% | — |
| CVE-2019-7137 | MED 6.5 | adobe bridge_cc Adobe Bridge CC versions 9.0.2 have a memory corruption vulnerability. Successful exploitation could lead to information disclosure. | 3.2% | — |
| CVE-2012-2418 | MED 6.8 | intuit quickbooks Heap-based buffer overflow in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allows remote attackers to cause a denial of ser | 3.2% | — |
| CVE-2025-27738 | MED 6.5 | microsoft windows_10_1507 Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network. | 3.2% | — |
| CVE-2017-8621 | MED 6.1 | microsoft exchange_server Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability". | 3.2% | — |
| CVE-2020-1563 | HIGH 7.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the | 3.2% | — |